← back to catalog · registered 2026-08-22 13:56

Subalzt/Qwen3-4B-Instruct-2507-abliterated-FP8

Subalzt Qwen 3.6B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Subalzt%2FQwen3-4B-Instruct-2507-abliterated-FP8"
Response includes
  • classification m1
  • files 9
  • benchmarks 11 entries
  • hub_downloads_all_time 48
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
48
31 last 30d - active
Likes
0
Model age
2mo ago
created 2026-08-11
Downloads over time
Now65→from0↑0%
02448720 on Aug 565 on Oct 11AugSepOct
Aug 5 → Oct 11 · 50 snapshots · spans 67 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Entertainment 0.4 UGI
Hazardous 1.2 UGI
Natural Intelligence 13.76 UGI
Political lean -12.4% UGI
Sensitive-Info 6.25 UGI
SocPol 0.5 UGI
UGI 15.83 UGI
Willingness (10) 3.5 UGI
W10-Adherence 1 UGI
W10-Direct 6 UGI
Writing 29.92 UGI

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en
Tags
transformers safetensors qwen3 text-generation fp8 compressed-tensors abliterated refusal-direction research interpretability conversational en

Related

Total size
4.84 GB
Files
9
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-11 03:12

Files by quantization

Auxiliary files 9 files 4.85 GB
model.safetensors 4.84 GB 366540cb download
tokenizer.json 10.9 MB 365ac76e download
README.md 3.47 KB 1ad156b1 download
config.json 2.83 KB 36c76ea8 download
chat_template.jinja 2.57 KB 70adff8a download
.gitattributes 1.53 KB 52373fe2 download
tokenizer_config.json 694 B c77896b9 download
generation_config.json 213 B 9efdfce4 download
recipe.yaml 176 B f4e66520 download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3-4B-Instruct-2507
base_model_relation: finetune
language:

  • en
    tags:
  • qwen3
  • fp8
  • compressed-tensors
  • abliterated
  • refusal-direction
  • research
  • interpretability
    pipeline_tag: text-generation
    library_name: transformers

Qwen3-4B-Instruct-2507 — Abliterated, FP8 (W8A8)

A research artifact: the "refusal direction" (Arditi et al. 2024,
arXiv:2406.11717) removed from
Qwen/Qwen3-4B-Instruct-2507,
then quantized to FP8. Its purpose is to measure the quality cost of
abliteration
with paired statistics on held-out data — a number the ecosystem
of "uncensored" uploads reports for essentially no one.

If you want a safety-aligned assistant, use the base model. This is an
instrument for studying what abliteration does to a model, published with the
measurements that justify that framing.

What was done

Closed-form, no training:

  1. Last-token residual activations collected for 128 refused prompts (AdvBench)
    vs. 128 harmless prompts (Alpaca), per layer.
  2. refusal_dir = normalize(mean(harmful) − mean(harmless)).
  3. Candidate layers swept by measured held-out refusal rate; layer 24
    (depth 0.67 of 36) won.
  4. Every residual-writing matrix orthogonalized against that direction
    (embed_tokens, per-layer o_proj and mlp.down_proj): W ← W − r̂(r̂ᵀW).
  5. Re-quantized to FP8 (FP8_DYNAMIC, per-channel weights + per-token dynamic
    activations, lm_head excluded) — identical recipe to the non-abliterated
    FP8 sibling.

Pipeline and eval code: https://github.com/Subalzt/qwen3-4b-quantized-fp8-gptq

Measured cost (paired, vs. the non-abliterated FP8)

Harness validated — the non-abliterated FP8 reproduced PPL 10.0415 to the digit.

metric base FP8 this model Δ paired test
Refusal (AdvBench held-out) 100% ~17% −83 pp intended effect
HumanEval pass@1 0.8659 0.8110 −5.49 pp McNemar p = 0.093 (not significant)
Perplexity (wikitext-2, ctx 2048) 10.0415 11.9987 +19.49% paired t, p ≈ 2e-112 (145/145 chunks worse)

The two capability metrics disagree, and that is the finding. A functional
code eval sees no significant loss; a dense per-token perplexity measure sees a
large, unambiguous degradation on every chunk. The +19.5% perplexity cost is
roughly 6× the +3.04% cost of 4-bit GPTQ quantization on the same model —
abliteration is a larger quality intervention than quantization itself.

Intended use

Research on safety-tuning mechanisms, refusal-direction interpretability,
quantization × behavioral-edit interaction, and robustness evaluation.

Limitations & responsible use

  • Refusal behavior is substantially reduced by design. It is not safety-
    aligned and will comply with many requests the base model declines. Deploy
    only with your own safeguards and within applicable law and the Apache-2.0
    terms inherited from the base model.
  • General language-modeling quality is measurably degraded (+19.5% PPL); do not
    treat it as quality-equivalent to the base.
  • FP8 (compressed-tensors) runs under vLLM / transformers on Linux. For native
    Windows use a GGUF build instead.

Run (vLLM)

vllm serve Subalzt/Qwen3-4B-Instruct-2507-abliterated-FP8 --max-model-len 8192

Citation

Arditi et al., Refusal in Language Models Is Mediated by a Single Direction,
2024. Base model © Qwen, Apache-2.0.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-11Add abliterated Qwen3-4B FP8 (W8A8) + measured-cost model card2e05d573.5 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration